How does OnFinality deal with personal information?

OnFinality, a web3 infrastructure platform, provides full disclosure on its privacy policy around personally identifiable information of users accessing its services.

How does OnFinality deal with personal information?

OnFinality is a blockchain infrastructure platform that saves web3 builders time and makes their lives easier. We deliver easy-to-use, reliable and scalable API endpoints for the biggest blockchain networks and empower developers to automatically test, deploy, scale and monitor their own blockchain nodes in minutes.

Over the past few months there has been significant discussion about the need for user privacy in key web3 infrastructure services, and the tradeoffs made in order to comply with increasingly stringent regulations in certain markets.

At OnFinality, we want to clarify exactly what our policy is around personally identifiable information, including the IP addresses of users accessing our services.

TL;DR

  1. OnFinality does not, and will never, correlate or link specific wallet addresses to the IP address or request origin making the RPC request
  2. We purge as much personal information as we can as fast as we can
  3. Everything that we do is with the intention to retain your trust in OnFinality as your reliable, independent, and high performing infrastructure partner

How we deal with personal information

OnFinality complies with various privacy protection laws around the world, notably the General Data Protection Regulation of the European Union (GDPR) and the equivalent laws of the United Kingdom (UK GDPR) when dealing with personal information.

Personal data means data that we collect directly or indirectly from you, e.g. when you visit our website or use our service. It includes elements like email address, names, billing information, and most importantly, IP addresses. While collecting IP addresses can be useful, it also raises privacy concerns since they can be used to identify a user’s location and potentially reveal other sensitive information.

How we manage IP addresses

For the sole purpose of providing our service, we temporarily record IP addresses and request origins headers of all requests.

We do this for a few key reasons:

  • To monitor free usage limits: For our public endpoints, the IP address is one of the best identifying IDs of a particular user (yes, we understand that it’s not perfect) and we use this to monitor that no single user is exceeding their free plan limits.
  • Provide efficient load balancing: We use IP addresses to correctly route traffic to the closest available node to maximise the performance of our service and ensure that your user receives the lowest latency and best service experience.
  • Prevent denial of service attacks against our infrastructure: We use IP addresses to constantly monitor for and block any denial of service attacks against our services and our infrastructure, ensuring reliability of service for valid users.
  • Analyse the geographic origin of requests: We use IP addresses to identify requests down to the country and region level (E.g. that the request came from California, USA), we then show this in your API insights and use the data at a network level to determine where best to locate our nodes for maximal performance.

We do not, and will never, correlate or link specific wallet addresses or transactions made over our infrastructure to the IP address or request origin making the RPC request.

After processing IP addresses to monitor usage limits, prevent denial of service attacks, and to identify the geographic source of the request (country and region level only), we discard the raw IP address value within 24 hours of that request being made to our servers.

We believe this strikes the best balance between minimal amounts of information that is required to act as the highest quality RPC infrastructure provider in web3, and we’re constantly looking for more ways that we can continue to preserve user confidentiality. You can read our full privacy policy on our website here.

If you have any questions or concerns regarding OnFinality’s Privacy Policy, please do not hesitate to reach out to us at support@onfinality.io and we will be in touch within one business day.

About OnFinality

OnFinality is a blockchain infrastructure platform that saves web3 builders time and makes their lives easier. OnFinality delivers scalable API endpoints for the biggest blockchain networks and empowers developers to automatically test, deploy, scale and monitor their own blockchain nodes in minutes. To date, OnFinality has served over hundreds of billions of RPC requests across 78 networks including Avalanche, BNB Chain, Cosmos, Polkadot, Ethereum, and Polygon, and is continuously expanding these mission-critical services so developers can build the decentralised future, faster!

App | Website | Twitter | Telegram | LinkedIn | YouTube